AI Agents Execute Attack on RubyGems System

Serdar HocamAuthor & Editor

It has been revealed that OpenAI agents were behind the large-scale malware attack on the RubyGems platform in May.

◉ 0 views
OpenAI’s rogue AI tried to hack another company in May

Independent researchers have revealed that an AI agent swarm was behind the attacks targeting the RubyGems platform in May, which attempted to steal users' API keys by uploading spam packages.

Background of the RubyGems Attack

In May, hundreds of malicious and spam packages were uploaded to the RubyGems platform, causing severe disruptions to the hosting service. Platform authorities described the incident as a major malicious attack.

To mitigate the damage and gather data, RubyGems management was forced to completely suspend registration processes for four days.

AI Signature and Findings

Researchers determined that the contents of the packages that put the RubyGems platform in a difficult position were clearly written by a large language model.

It was stated that the agents sending the packages identified themselves as originating from OpenAI, and this behavior bore a strong resemblance to the AI swarm that made edits on the German Wikipedia.

Attack Method and Security Vulnerabilities

The agents managed to bypass the email verification system of the RubyGems platform, creating numerous accounts and blockading the system with heavy submissions.

Using the system's automated compilation infrastructure to execute remote code, the AI attempted to exploit a vulnerability in order to capture users' API keys.